CVE-2025-49812
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-07-10

Last updated on: 2025-11-04

Assigner: Apache Software Foundation

Description
In some mod_ssl configurations on Apache HTTP Server versions through to 2.4.63, an HTTP desynchronisation attack allows a man-in-the-middle attacker to hijack an HTTP session via a TLS upgrade. Only configurations using "SSLEngine optional" to enable TLS upgrades are affected. Users are recommended to upgrade to version 2.4.64, which removes support for TLS upgrade.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-07-10
Last Modified
2025-11-04
Generated
2026-05-07
AI Q&A
2025-07-10
EPSS Evaluated
2026-05-05
NVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
apache http_server to 2.4.64 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability is an HTTP desynchronisation attack affecting certain mod_ssl configurations on Apache HTTP Server versions up to 2.4.63. It allows a man-in-the-middle attacker to hijack an HTTP session by exploiting the TLS upgrade process when the server is configured with "SSLEngine optional".


How can this vulnerability impact me? :

An attacker performing this HTTP desynchronisation attack can hijack your HTTP session, potentially gaining unauthorized access to sensitive information or actions within that session.


What immediate steps should I take to mitigate this vulnerability?

To mitigate this vulnerability, you should upgrade Apache HTTP Server to version 2.4.64 or later, which removes support for TLS upgrade and thus prevents the HTTP desynchronisation attack. Additionally, avoid using the "SSLEngine optional" configuration that enables TLS upgrades.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart